Full briefing
Markdown renderedMSP Threat Radar Weekly Briefing — Week of 2026-08-10
This week’s briefing tracks 12 recent watch items across 3 vendors, with emphasis on active service incidents and high-priority operational issues.
Top items
ClamAV Vulnerabilities Affecting Cisco Products: August 2026
- Vendor: Cisco
- Published: 2026-08-10
- Status: watch
- Source: cisco
- Official advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26
Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For additional information on these vulnerabilities in ClamAV, see the ClamAV blog. Cisco plans to release software updates that address these vulnerabilities in affected Cisco platforms. There are no workarounds that address these vulnerabilities. Notes: The Security Impact Rating (SIR) for these vulnerabilities is High for Windows-based platforms only because those platforms run the ClamAV scanning process in a privileged security context. The platforms that are highly impacted include Cisco Secure Endpoint Connector for Windows. The SIR for these vulnerabilities is Medium on other platforms, including Linux and Mac platforms, because those platforms run the ClamAV scanning process in a lower-privileged security context. The affected platforms include Secure Endpoint Connector for Linux and Mac. Cisco Secure Endpoint Private Cloud itself is not impacted by these vulnerabilities. However, the Cisco Secure Endpoint Connector software that is distributed from the device is impacted. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26 <br/>Security Impact Rating: High <br/>CVE: CVE-2026-20337,CVE-2026-20338,CVE-2026-20339,CVE-2026-20345,CVE-2026-20346,CVE-2026-20347,CVE-2026-20348
Review the official advisory, map affected products against managed client environments, and determine whether patching or temporary mitigation is required.
NVD watch item CVE-2026-10579
- Vendor: NVD
- Published: 2026-08-11
- Status: watch
- Source: nvd
- Official advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-10579
A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to restricted operations, or other flaws.
Review the official advisory, map affected products against managed client environments, and determine whether patching or temporary mitigation is required.
NVD watch item CVE-2026-19425
- Vendor: NVD
- Published: 2026-08-11
- Status: watch
- Source: nvd
- Official advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-19425
Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.
Review the official advisory, map affected products against managed client environments, and determine whether patching or temporary mitigation is required.
NVD watch item CVE-2026-44758
- Vendor: NVD
- Published: 2026-08-11
- Status: watch
- Source: nvd
- Official advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-44758
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability of the application.
Review the official advisory, map affected products against managed client environments, and determine whether patching or temporary mitigation is required.
NVD watch item CVE-2026-34265
- Vendor: NVD
- Published: 2026-08-11
- Status: watch
- Source: nvd
- Official advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-34265
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application.
Review the official advisory, map affected products against managed client environments, and determine whether patching or temporary mitigation is required.
